Vulnerability  ·  2026-08-13

TypeBot chatbot builder — cleartext API token storage enables credential theft

VulnerabilityHigh impactGlobalCVE-2026-47702
NVD published CVE-2026-47702 (CVSS 9.1, Critical) describing cleartext storage of sensitive builder API credentials in the TypeBot database.
Compounds the impact of any other TypeBot data-access bug (of which several were published in the same window) since database access alone directly yields usable authentication tokens for the chatbot builder API.
Builder API bearer tokens are stored in the database as cleartext strings rather than hashed/encrypted; an attacker who gains any read access to the database can extract usable API tokens directly.
TypeBot 3.16.1
Upgrade to TypeBot >= 3.17.0; rotate all API tokens after upgrade.
NVD - CVE-2026-47702
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →